Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
GHSA-g7vj-qw6x-g3p8Critical· 9.8Duplicate Advisory: PickleScan has multiple stdlib modules with direct RCE not in blocklist
GHSA-q8qp-8jq6-78mcHigh· 8.1Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper
GHSA-gq8p-2329-gh3xHigh· 8.1Duplicate Advisory: Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions
GHSA-x36p-c636-788xHigh· 8.1Duplicate Advisory: Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval
GHSA-mg57-j93w-g3c7High· 8.1Duplicate Advisory: Picklescan has a missing detection when calling built-in python profile.Profile.runctx
GHSA-fh2f-24rh-r2vqHighDuplicate Advisory: Picklescan missing detection when calling built-in python library function timeit.timeit()
GHSA-fcqg-3mwf-cfcfHigh· 8.1Duplicate Advisory: Picklescan is missing detection when calling built-in Python cProfile.runctx
GHSA-8mc5-7w9m-fqv6High· 8.1Duplicate Advisory: Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand
GHSA-qvp4-q2p5-22ggHigh· 8.1Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config
GHSA-6v84-v468-3c7fCritical· 9.8Duplicate Advisory: Picklescan has Incomplete List of Disallowed Inputs
GHSA-rmpp-8wf5-xx5qCritical· 9.8Duplicate Advisory: Picklescan vulnerable to Arbitrary File Writing
GHSA-7f79-rvx6-vxc4Critical· 9.8Duplicate Advisory: Picklescan does not block ctypes
GHSA-5rph-q42j-36j9Critical· 9.8Duplicate Advisory: Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass
GHSA-5gp7-4733-2w2vHigh· 8.8Duplicate Advisory: Picklescan Bypasses Unsafe Globals Check using pty.spawn
GHSA-82fg-2r99-h7v6Critical· 10.0Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass
GHSA-5v23-73v4-w2fpHigh· 7.5Duplicate Advisory: picklescan has Arbitrary file read using `io.FileIO`
GHSA-j6c9-qvp8-699fCritical· 9.8Duplicate Advisory: picklescan missing detection by simple obfuscation of a `builtins.eval` call
GHSA-cc5p-54x3-hcf8HighDuplicate Advisory: Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER
GHSA-4mpj-78p6-rj59Critical· 9.8Duplicate Advisory: PickleScan's profile.run blocklist mismatch allows exec() bypass
CVE-2026-56315Critical· 9.8PickleScan has multiple stdlib modules with direct RCE not in blocklist
CVE-2026-53875HighPicklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER
CVE-2026-56304Mediumpicklescan vulnerable to arbitrary file create using logging.FileHandler
CVE-2026-53874Highpicklescan missing detection by simple obfuscation of a `builtins.eval` call
CVE-2026-53872High· 7.5picklescan has Arbitrary file read using `io.FileIO`
CVE-2025-71339MediumPicklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.